Loading market data...
← Back to CVE feed

CVE-2026-101084

CRITICAL CVSS 9.6 View on NVD ↗

Description

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Published: Sep 27, 2026 21:17 UTC Modified: Sep 27, 2026 21:17 UTC